6.5 Million Passwords Leaked: Inside the Mansory 1 Telegram Log
In December 2025, a Telegram user uploaded a stealer log file labeled "Mansory 1" containing 6,524,405 records. The dump includes email addresses, plaintext passwords, and the URLs of the accounts those passwords open, all pulled directly from malware-infected computers. HEROIC's threat intelligence team has verified this data as authentic and added it to our breach database, which now tracks details from more than 400 billion exposed records worldwide.
Why the Mansory 1 Leak Is So Large and So Risky
At over 6.5 million records, Mansory 1 is one of the larger stealer log collections HEROIC has catalogued recently. Unlike a breach where hackers break into one company's servers, a stealer log like this one is assembled from thousands of individually infected devices, each contributing whatever passwords and browsing data the malware could find. That scale means the file likely touches accounts across hundreds of different websites and services, not just one platform. Because the passwords were captured in plaintext, anyone who gets a copy of the file can read your login details immediately, no cracking required.
What Was Exposed in the Mansory 1 Dump
- Email addresses
- Plaintext passwords
- URLs identifying which site or service each password belongs to
Having the exact login URL next to each email and password pair removes any guesswork for an attacker. They can jump straight to the correct login page and attempt to sign in right away.
Why This Matters for You
If any of your credentials appear in a file this size, you're exposed to credential stuffing, where attackers run stolen email and password pairs against banking sites, email providers, and online retailers hoping for a reused password. A single successful login can lead to account takeover, and from there to identity theft or direct financial fraud. Because stealer logs bundle everything from one infected machine, other personal details saved on that device could be compromised too.
How a Stealer Log This Size Gets Built
Info-stealing malware spreads through malicious downloads, cracked software, phishing attachments, and fake update prompts. Once it lands on a device, it silently harvests every saved password, cookie, and autofill entry, then sends the haul back to whoever controls the malware. Logs from many infected victims are often combined into a single large file, like Mansory 1, before being shared or sold on Telegram channels and underground marketplaces.
Check If You Are Affected
With millions of records involved, it's worth checking now rather than later. HEROIC's free breach scanner searches your email address against more than 400 billion leaked and stolen records, including stealer logs like Mansory 1. Run a free scan today, and if you find a match, change the affected passwords right away and turn on multi-factor authentication wherever it's supported.
Breach Breakdown
6,524,405 passwords exposed. Is yours one of them?
Enter your email to scan this breach plus 400B+ other leaked records. If you're compromised, we'll show you exactly where and what to change.
Free forever · No account required · Results in seconds